upvote
That's not how auditing works as I have observed it. Either your stuff is critical, or not. And when it is then everything which touches data sees an audit and no password policy incl. Shared and weak credentials is the first thing that would have been spotted. I would assume they buried some stuff to deep in a hierarchy and 3rd service partners that this company in the end got no proper audit.
reply
Maybe I'm missing the point but isn't the parent comment asking with the admin accounts had no 2FA?
reply
Oh no! Cost! Friction! Better just half-ass it then.
reply
We're talking about a country with 6 million inhabitants, of which a large number is old and/or barely computer-literate and/or barely actually literate. Or doesn't possess a smartphone at all and only uses government services from a public computer in a library.

Government services have to work in all these scenarios, simply because that is a right of the citizens.

reply